Electronic Health Records and Privacy: Public Concerns, Public Choices
|
|
|
- Hollie Cummings
- 10 years ago
- Views:
Transcription
1 Electronic Health Records and Privacy: Public Concerns, Public Choices Dr. Alan F. Westin Professor of Public Law and Government Emeritus, Columbia University and Director, Health Privacy Program, PRIVACY CONSULTING GROUP at the Harvard Privacy Symposium, August 22, 2007
2 My Experiences with HC and Privacy opinion surveys and empirical field studies my prime tools developer of 10 national surveys on HC and privacy since 1978 field studies for NAS, NBS AND OTA -- e.g. Computers, Health Records, and Citizen Rights (1975) policy proposals, e.g. Building Privacy by Design into Emerging EHR Systems (2005) speeches at national health forums: AHRQ, IBM, Markle, etc. since 1993, privacy assessments for HC providers, insurers, pharmacy firms, and HR departments, through my Privacy Consulting Group (PCG)
3 Pre-EHR Privacy Surveys health information most sensitive personal information trust in HC practitioners to handle PHI very high main worry: health information going to non-health organizations or publicly disclosed concerns also over data security and uses of new genetic information public majority ambivalent about HC computer effects -- a worried positive led to demands for -- and passage of -- federal health privacy law and additional state laws but HIPAA Privacy Rule and enforcement not seen as solving all privacy problems, even pre-ehr
4 Surveys on EHR and Privacy 23 published surveys with health privacy Qs, Three Harris surveys I will draw on most: Harris/Westin, on EHR and Privacy; online, 2747 adult respondents, September, 2006; adjusted to represent entire adult population Harris /Wall St. Journal, Health Care Poll; online, 2624 adult respondents, September Harris-Westin, Uses of Personal Health Information; 2337adult respondents; January, 2007
5 Low Awareness of EHR National Program Harris/Westin 2006 described current U.S. EHR national program efforts; asked: Have you read or heard anything about this program? only 26% of the adult public said yes; represents r 60 million out of 230 million adults. (62% said had not read or heard; 12% weren t t sure) About the same result as in 2005 awareness highest -- as expected -- among better-educated, higher-income, and online-using rather surprising -- given extensive mass media coverage 3 out of 4 adults not yet involved with or paying attention to EHR developments
6 Online Users See EHR Positives Harris-WSJ 2006 documented broad public optimism re EHR benefits -- but at lower majorities than recorded in 2005 WSJ survey 55% believe EHR can decrease frequency of medical errors significantly (was 62% in 2005) 60% believe EHR can reduce healthcare costs significantly (was 73% in 2005) 68% believe EHR can improve patient care by reducing unnecessary tests and procedures (was 73% in 2005) 62% of online users also believe The use of Electronic Medical Records makes it more difficult to ensure patients privacy (was 67% in a small gain in confidence)
7 EHR Privacy Concerns, From Harris/Westin 2005 sensitive health data may be leaked % increased sharing without patient s s knowledge % may be inadequate data security % could increase not decrease medical errors % computer-worried patients won t t give sensitive information to providers % federal health privacy rules will be reduced... 62%
8 EHR Developers and Privacy and Security when asked how much attention developers and managers of EHR programs are paying to insure adequate patient privacy and data security measures 69% think they are paying attention (36% a great deal and 33% some ) 19% did not think so (12% paying only a little attention and 7% paying not much attention at all ) positive belief is an EHR system developers asset -- for now
9 How Public Sees Privacy Risks and Benefits when asked whether expected benefits to patients and society of EHR systems outweigh potential risks to privacy OR whether privacy risks outweigh expected benefits, privacy fears trump potential benefits: 42% feel privacy risks outweigh expected benefits 29% feel expected benefits outweigh the privacy risks BUT -- 29% say they are not sure shows that the creation of a majority opinion on the risk-benefit judgment is still out there -- not yet formed will be shaped by what EHR system developers DO and how they COMMUNICATE to patients and public also by debates in Congress over privacy rules for EHR programs
10 Latest Harris-Westin Probe % satisfied with how doctors and hospitals protect privacy By 63-25%, believe increased use of electronic records can be accomplished without jeopardizing proper patient privacy rights. By 60-27%, believe existing federal and state health privacy protection laws provide a reasonable level of privacy By 63-27%, would consent to have their medical records used for medical research as long as there were guarantees that no personally-identifying information would be released The 25-27% with Intense Health Privacy Concerns matches the 25-30% of the public expressing Intense Consumer Privacy
11 Key Emerging Issue -- Consumer Participation in EHR Programs most major EHR programs being rolled out without advance descriptions and choices for patients or members, as just an administrative enhancement is NOT how a majority of patients or members feel this change should be carried out: Harris/Westin 2006 survey asked: How would you like to be involved when organizations providing you with health care records transition from mostly paper records to a complete electronic health record system? Please select ONE answer that best represents your view
12 Majorities (60%) Want to Be Informed and/or Exercise Choices four answers provided I might be okay with this but I would want to be notified of this change and have the effects of the handling of my personal medical information explained to me..27% I might be okay with this but I would want to be able to designate which parts of my medical records were entered or not entered into the electronic health record system..12%
13 Patient/Member Involvement -- 2 I would want to be given the right not to have any of my medical records entered into the new electronic record system.. 21% I don t need to be notified of the change since I don t think it will affect my relationship with my doctors and how they handle my information. 22% Not sure.. 17% (note the large figure here) while resting on low public majority awareness of EHR programs, these attitudes spell major potential trouble for EHR efforts
14 What is Being Done to Inform and Offer Choices? not aware of any field studies of how EHR programs are being introduced to patients or members and how new EHR-based rights are presented not aware of patient/member surveys at EHR sites exploring how consumers react to the changes and rights policies also not aware of any experiments with allowing patients or members the right to designate record portions not to go into the general EHR system, and if these are being studied Finally, are there any EHR programs that offer a general opt out? If so, are these being studied?
15 A Looming Conflict? given 42+% of public feeling potential privacy risks outweigh potential EHR benefits and 60% of the public wanting advance explanations of EHR impacts and rights to choose how records used could be a sharp bump ahead for EHR developers, as weak communications and a just say yes approach prevail also, patient rights groups and privacy advocates calling for new EHR-privacy rules in Congress push-back already happening in UK, where 53% of public and 52% of GPs oppose the UK national EHR plan, in organized campaign
16 Informing Can Be Done Well every EHR program should develop and provide a Patient s Guide to Your New EHR System: For Enhanced Participation, Privacy and Security customized to each EHR system; cover changes to all health care processes and information uses spell out health-care advantages of new system show opportunities for greater patient participation in own health care processes and individual EHR-program choices describe privacy/fair information practices rules and rights under EHR, in clear, non-hipaa-style prose outline data security program and safeguards offer lively Qs and As, scenarios, and personal contacts
17 Implications privacy and data security remain absolutely critical issues for the national EHR effort and each individual system majorities fear privacy risks, but adequate patient and member communications and choice options not present yet calls for empirical field studies of the EHR introduction process, patient and member communications, and new privacy, security, and participation policies along with surveys of patient and member perceptions, concerns, and experiences in various EHR program settings now is the right time in EHR activities for such studies -- not too soon and not too late
18 Westin/PCG publications and ppt presentations PCG website under reconstruction; please contact me at to obtain these materials 1. Building Privacy by Design into Emerging Electronic Health Record systems, White Paper, Public Attitudes Toward Privacy and EHR Programs, AHRQ Conference, Beyond HIPAA: Assuring Patients Interests in EHR Programs, IBM Forum, Patient Participation and Privacy in EHR Programs, IBM Forum Uses of Personal Health Information, Harris-Westin, 2007
Electronic Communication In Your Practice. How To Use Email & Mobile Devices While Maintaining Compliance & Security
Electronic Communication In Your Practice How To Use Email & Mobile Devices While Maintaining Compliance & Security Agenda 1 HIPAA and Electronic Communication 2 3 4 Using Email In Your Practice Mobile
Networked Personal Health Records
Networked Personal Health Records Table of Contents Potential of Personal Health Records (PHRs) What is a PHR? Common functions of a PHR Ideal attributes The PHR environment Consumer perceptions about
INTRODUCTION. The HIPAA Privacy Rule and Electronic Health Information Exchange in a Networked Environment
INTRODUCTION This guidance is composed of a series of fact sheets that clarify how the HIPAA Privacy Rule applies to, and can be used to help structure the privacy policies behind, electronic health information
HIPAA Privacy Overview
HIPAA Privacy Overview General HIPAA stands for a federal law called the Health Insurance Portability and Accountability Act. This law, among other purposes, was created to protect the privacy and security
Wolters Kluwer Health Quarterly Poll: Medical Mistakes
Wolters Kluwer Health Quarterly Poll: Medical Mistakes New poll reveals consumer perspectives on medical errors Wolters Kluwer Health has new data from its latest quarterly poll probing the changes taking
U.S. Department of Health and Human Services. U.S. Department of Education
U.S. Department of Health and Human Services U.S. Department of Education Joint Guidance on the Application of the Family Educational Rights and Privacy Act (FERPA) And the Health Insurance Portability
HIPAA for HIT and EHRs. Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals
HIPAA for HIT and EHRs Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals Donald Bechtel, CHP Siemens Health Services Patient Privacy Officer Fair Information Practices
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) BUSINESS ASSOCIATE AGREEMENT
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) BUSINESS ASSOCIATE AGREEMENT This HIPAA Business Associate Agreement ( BAA ) is by and between the National Association of Boards of Pharmacy
Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA)
HUMAN RESOURCES Index No. VI-35 PROCEDURES MEMORANDUMS TO: FROM: SUBJECT: MCC Personnel Office of the President Guidelines Relating to Implementation of the Privacy Regulations of the Health Insurance
Healthcare Applications and HIPAA. BA590-IT Governance Final Term Project Prof. Mike Shaw
Healthcare Applications and HIPAA BA590-IT Governance Final Term Project Prof. Mike Shaw Michael McIntosh 5/4/2007 Table of Contents 1. Abstract 3 2. Introduction 3 3. Section 1: HIPAA definition and history
NOTICE OF PRIVACY PRACTICES
THE PHYSICIAN PRACTICE, P.A. NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW
NOTICE OF PRIVACY PRACTICES
NOTICE OF PRIVACY PRACTICES This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully. A federal regulation,
Huseman Health Law Group
Huseman Health Law Group William Rusty Huseman, Esq. 3733 University Blvd. West, Suite 305-A Jacksonville, Florida 32217 Telephone: (904) 448-5552 Facsimile: (904) 448-5653 Email: [email protected]
COLLECTION, USE, AND DISCLOSURE LIMITATION
COLLECTION, USE, AND DISCLOSURE LIMITATION This is one of a series of companion documents to The Nationwide Privacy and Security Framework for Electronic Exchange of Individually Identifiable Health Information
Copayment Is Due At Time Of Visit. Self-pay (payment due at time of service)
REGISTRATION FORM Please present your insurance card and photo ID at time of check-in. Settlement of patient financial responsibility is expected at time of service. Copayment Is Due At Time Of Visit.
Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information
Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information about HIPAA, the HITECH-HIPAA Omnibus Privacy Act, how
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT Please complete the following and return signed via Fax: 919-785-1205 via Mail: Aesthetic & Reconstructive Plastic Surgery, PLLC 2304 Wesvill Court Suite 360 Raleigh, NC 27607
Meeting the HIPAA Training and Business Associate Requirements Questions and Answers, with HIPAA Security Expert Mike Semel
Meeting the HIPAA Training and Business Associate Requirements Questions and Answers, with HIPAA Security Expert Mike Semel Questions Answers 1 Is a Business Associate (BA) responsible for assuming a Covered
On April 15, 2002, Washington DC Mayor Anthony Williams spoke at an event led by
Discontent in DC By Mark David Richards On April 15, 2002, Washington DC Mayor Anthony Williams spoke at an event led by civic leaders to protest DC s unequal political status. It is not acceptable, he
ELECTRONIC HEALTH RECORDS
ELECTRONIC HEALTH RECORDS Understanding and Using Computerized Medical Records CHAPTER TEN LESSON ONE Privacy and Security of Health Records Understanding HIPAA HIPAA: acronym for Health Insurance Portability
GP-led health centres. Background Briefing
GP-led health centres Background Briefing Equitable Access to Primary Medical Care Lord Darzi is an eminent surgeon who is currently serving as a junior health minister. In June 2007 the Secretary of State
Metropolitan Living, LLC 151 W. Burnsville Parkway, Suite 101 Burnsville, MN 55337 Ph: (952) 564-3030 Fax: (651) 925-0031
The Health Insurance Portability and Accountability Act (HIPAA) and Client Privacy Statement This notice describes how your medical information may be used and disclosed and how you can get access to this
Social Media. IMO Position Paper on. April 2013. Irish Medical Organisation 10 Fitzwilliam Place Dublin 2
Ceardchumann Dochtúirí na héireann IMO Position Paper on Social Media April 2013 Irish Medical Organisation 10 Fitzwilliam Place Dublin 2 Tel: (01) 6767 273 Fax: (01) 6612 758 Email: [email protected] Website:
WELCOME TO STRAITH HOSPITAL FOR SPECIAL SURGERY OUR PHILOSOPHY JOINT NOTICE OF PRIVACY PRACTICES
WELCOME TO STRAITH HOSPITAL FOR SPECIAL SURGERY During your stay with us, our goal is to make your hospital experience as favorable as possible by providing information and open channels of communication.
USES AND DISCLOSURES FOR TREATMENT, PAYMENT, AND HEALTH CARE OPERATIONS [45 CFR 164.506]
USES AND DISCLOSURES FOR TREATMENT, PAYMENT, AND HEALTH CARE OPERATIONS [45 CFR 164.506] Background The HIPAA Privacy Rule establishes a foundation of Federal protection for personal health information,
what your business needs to do about the new HIPAA rules
what your business needs to do about the new HIPAA rules Whether you are an employer that provides health insurance for your employees, a business in the growing health care industry, or a hospital or
SOUTH CAROLINA PUBLIC EMPLOYEE BENEFIT AUTHORITY (PEBA) NOTICE OF PRIVACY PRACTICES
SOUTH CAROLINA PUBLIC EMPLOYEE BENEFIT AUTHORITY (PEBA) NOTICE OF PRIVACY PRACTICES Effective April 14, 2003 Revised September 23, 2013 This notice describes how medical information about you may be used
The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq.
The HITECH Act: Implications to HIPAA Covered Entities and Business Associates Linn F. Freedman, Esq. Introduction and Overview On February 17, 2009, President Obama signed P.L. 111-05, the American Recovery
Notice of Privacy Practices
Notice of Privacy Practices This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully. This Notice of
NOTICE OF PRIVACY PRACTICES. for Sony Pictures Entertainment Inc.
NOTICE OF PRIVACY PRACTICES for Sony Pictures Entertainment Inc. [Para recibir esta notificación en español por favor llamar al número proviso en este documento.] This notice describes how medical information
ACKNOWLEDGMENT OF RECEIPT OF NOTICE OF PRIVACY PRACTICES
ACKNOWLEDGMENT OF RECEIPT OF NOTICE OF PRIVACY PRACTICES I acknowledge that I have been provided a copy of Fiorillo Cosmetic and General Dentistry s Notice of Privacy Practices, which has an effective
Impact of Breast Cancer Genetic Testing on Insurance Issues
Impact of Breast Cancer Genetic Testing on Insurance Issues Prepared by the Health Research Unit September 1999 Introduction The discoveries of BRCA1 and BRCA2, two cancer-susceptibility genes, raise serious
Infinedi HIPAA Business Associate Agreement RECITALS SAMPLE
Infinedi HIPAA Business Associate Agreement This Business Associate Agreement ( Agreement ) is entered into this day of, 20 between ( Company ) and Infinedi, LLC, a Limited Liability Corporation, ( Contractor
HIPAA Privacy FAQ s. 3. Generally, what does the HIPAA Privacy Rule require the average provider or health plan to do?
HIPAA Privacy FAQ s 1. What is the HIPAA privacy regulation? Until Congress passed HIPAA in 1996, personal health information (PHI) was protected by a patchwork of federal and state laws. Patients health
Detailed Notice of Privacy Practices Effective Date: September 20, 2013
Detailed Notice of Privacy Practices Effective Date: September 20, 2013 Purpose of This Notice: This Notice describes your legal rights, advises you of our privacy practices, and lets you know how Butler
Salt Lake Community College Employee Health Care Benefits Plan Notice of Privacy Practices
THIS NOTICE DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. Date: June 1, 2014 Salt Lake Community College
Parents recording social workers - A guidance note for parents and professionals
Parents recording social workers - A guidance note for parents and professionals The Transparency Project December 2015 www.transparencyproject.org.uk [email protected] (Charity Registration
Building Trust and Confidence in Healthcare Information. How TrustNet Helps
Building Trust and Confidence in Healthcare Information The management of healthcare information in the United States is regulated under the HIPAA (Health Insurance Portability and Accountability Act)
Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview
Updated HIPAA Regulations What Optometrists Need to Know Now The U.S. Department of Health & Human Services Office for Civil Rights recently released updated regulations regarding the Health Insurance
TELLING PEOPLE YOU HAVE NEUROFIBROMATOSIS TYPE 1. StLouisChildrens.org
TELLING PEOPLE YOU HAVE NEUROFIBROMATOSIS TYPE 1 StLouisChildrens.org Introduction Neurofibromatosis Type 1 (NF1) is a common genetic condition that can cause a wide variety of medical problems in different
HIPAA PRIVACY AND SECURITY AWARENESS
HIPAA PRIVACY AND SECURITY AWARENESS Introduction The Health Insurance Portability and Accountability Act (known as HIPAA) was enacted by Congress in 1996. HIPAA serves three main purposes: To protect
Life Insurance Policy Information. Policyowner(s) (please print clearly) insurance company policy number issue date (00/00/0000)
L I F E S E T T L E M E N T Q U E S T I O N N A I R E (please print clearly) Life Insurance Policy Information insurance company policy number issue date (00/00/0000) face amount total policy loan cash
HIPAA MANUAL. Most health plans and health care providers that are covered by the new Rule must comply with the new requirements by April 14, 2003.
HIPAA MANUAL What is HIPAA? Health Insurance Portability and Accountability Act. The Health Insurance Portability and Accountability Act (HIPAA) provides rights and protections for participants and beneficiaries
REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES PLEASE REVIEW IT CAREFULLY.
REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW PROTECTED HEALTH INFORMATION (PHI) ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS
EMPLOYEE WELLNESS KEY ELEMENTS FOR A SUCCESSFUL PROGRAM
EMPLOYEE WELLNESS KEY ELEMENTS FOR A SUCCESSFUL PROGRAM 1 ABOUT THIS DOCUMENT Many employers have launched employee wellness programs in recent years with different degrees of success or failure. What
HIPAA Privacy & Security Rules
HIPAA Privacy & Security Rules HITECH Act Applicability If you are part of any of the HIPAA Affected Areas, this training is required under the IU HIPAA Privacy and Security Compliance Plan pursuant to
Notice of Privacy Practices
Notice of Privacy Practices THIS NOTICE OF PRIVACY PRACTICES DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
BUSINESS ASSOCIATE AGREEMENT
BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement is effective September 1, 2013 and made between Community Health Solutions of America, Inc., a Florida corporation ( CHS ) and ( Company ).
HIPAA Compliance Strategies for Pharmaceutical Manufacturers,
HIPAA Compliance Strategies for Pharmaceutical Manufacturers, PBMs and Pharmacies Jean-Paul Hepp,, Ph.D. Director, Global Privacy HIPAA Colloquium Harvard MA; August 22, 2002 1 Agenda Privacy ~ Definitions
Psychiatric Associates of Atlanta, LLC Twelve Piedmont Center, Suite 410 3495 Piedmont Road, NE Atlanta, GA 30305 404-495-5900 404-495-5901 (fax)
PATIENT INFORMATION: Psychiatric Associates of Atlanta, LLC Twelve Piedmont Center, Suite 410 3495 Piedmont Road, NE Atlanta, GA 30305 404-495-5900 404-495-5901 (fax) Last Name: First: MI: Address: City:
Target Audience: All Non-Management CHS Employees, Students, Volunteers, and Physicians
This self-directed learning module contains information all CHS employees are expected to know in order to protect our patients protected health information. Target Audience: All Non-Management CHS Employees,
Client Privacy Notice (HIPAA)
Client Privacy Notice (HIPAA) Privacy Statement Northern Human Services is required by law to maintain the privacy of Protected Health Information (PHI) and to provide individuals, this NOTICE OF PRIVACY
Retiree Questions from the Conference Calls for Healthcare CenturyLink
Retiree Questions from the Conference Calls for Healthcare CenturyLink Miscellaneous Questions 1. If I have a pre-existing condition, such as Parkinson s, will I have trouble getting insurance? No, not
PLLC NOTICE OF PRIVACY PRACTICES
PLLC THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE READ IT CAREFULLY. NOTICE OF PRIVACY PRACTICES The following
Health Insurance Portability and Accountability Act HIPAA. Glossary of Common Terms
Health Insurance Portability and Accountability Act HIPAA Glossary of Common Terms Terms: HIPAA Definition*: PHCS Definition/Interpretation: Administrative Simplification HIPAA Subtitle F It is the purpose
Patti Levin, LICSW, Psy.D. Clinical Psychologist
Patti Levin, LICSW, Psy.D. Clinical Psychologist 673 Boylston St. #4. 617.227.2008 Boston, MA02116 fax: 617.247.7523 www.drpattilevin.com email:[email protected] Notice of Privacy Practices (HIPAA)
NOTICE OF PRIVACY PRACTICES
GLOUCESTER COUNTY PUBLIC SCHOOLS EMPLOYEE HEALTH CARE PLAN, GLOUCESTER COUNTY PUBLIC SCHOOLS EMPLOYEE DENTAL CARE PLAN, GLOUCESTER COUNTY PUBLIC SCHOOLS EMPLOYEE FLEXIBLE BENEFITS PLAN 1 NOTICE OF PRIVACY
